Ransomware Gangs Actively Exploiting SonicWall SMA1000 Vulnerabilities, CISA Confirms
Ransomware groups have begun exploiting two recently patched vulnerabilities in **SonicWall** SMA1000 secure remote access gateways, including a critical server-side request forgery (SSRF) flaw. The **U.S. Cybersecurity and Infrastructure Security Agency (CISA)** has confirmed active exploitation, adding these flaws to its Known Exploited Vulnerabilities (KEV) Catalog and urging immediate patching by federal agencies.

**CISA** has issued a critical warning: ransomware gangs are now actively exploiting two recently patched vulnerabilities in **SonicWall** SMA1000 appliances. These include a maximum-severity server-side request forgery (SSRF) flaw, posing significant risks to organizations relying on these secure remote access gateways.
SMA1000 devices are widely utilized by large corporations, government agencies, and Managed Service Service Providers (MSSPs) to facilitate VPN access to internal applications and corporate networks.
**SonicWall** released patches for these security flaws, tracked as **CVE-2026-15409** and **CVE-2026-15410**, in mid-July. At the time, the company warned of zero-day exploitation already underway.
"**SonicWall** PSIRT has investigated multiple cases indicating the active exploitation of the vulnerabilities described in this advisory," the company stated. "Customers are strongly urged to upgrade to the hotfix release as soon as possible to remediate these vulnerabilities."
Incident response firm **Volexity** later revealed that a threat actor, tracked as **UTA0533**, began exploiting these vulnerabilities as early as June 22. This was weeks before **SonicWall** publicly disclosed the flaws. The group used these exploits to deploy custom malware, including **KNUCKLEBALL**, **Sou5**, **ROOTRUN**, and **ORANGETAIL**, on vulnerable VPN appliances.
Internet security watchdog **Shadowserver** currently identifies over 380 SMA1000 appliances exposed online. While some may have been secured, many remain vulnerable to attack.

**CISA** added both **CVE-2026-15409** and **CVE-2026-15410** to its KEV Catalog on July 14, mandating that Federal Civilian Executive Branch (FCEB) agencies patch their systems within three days.
"This type of vulnerability is a frequent attack vector for malicious cyber actors and poses significant risks to the federal enterprise," the cybersecurity agency emphasized.
Although **SonicWall** has yet to update its official advisory to confirm ransomware-specific exploitation, **CISA**'s recent updates to the KEV Catalog explicitly flag these vulnerabilities as being targeted by ransomware gangs.
This isn't the first time **SonicWall** SMA1000 devices have been in the crosshairs. In December, the company warned customers to patch another vulnerability, **CVE-2025-40602**, in the **SonicWall** SMA1000 Appliance Management Console (AMC). This flaw was being chained by attackers in zero-day attacks to gain root privileges.
Just a month prior, **SonicWall** attributed a September security breach, which exposed customers' firewall configuration backup files, to state-sponsored hackers. This followed warnings about over 100 **SonicWall** SSLVPN accounts being compromised using stolen credentials. In September, the company also released a firmware update to remove **OVERSTEP** rootkit malware deployed in attacks targeting SMA 100 series devices.